MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d388917582a8cb3e76fdd2cfddd009a456feb3863328e018821bb359d74ff12. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 2d388917582a8cb3e76fdd2cfddd009a456feb3863328e018821bb359d74ff12
SHA3-384 hash: 63c7af3b278d3c77d709ffd819383a428668c32eba7b7725d229fc1b15f46fa567f3220f0a09bbd4970b5c82ae51b771
SHA1 hash: 3579f9e2ace4eae0f6b98d3f125af6063637b971
MD5 hash: 25a1c05c1798e37cf9bbe174b68faacf
humanhash: single-seventeen-coffee-cat
File name:gtop.sh
Download: download sample
Signature Gafgyt
File size:1'595 bytes
First seen:2025-11-03 15:05:03 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:vcCMcCcTcCvWLcChNIRksc8scUZAcW+cmmJcBbcZcRascMc4kcCtXKQ:vwQ7WLyJENKczk08Qb44khXh
TLSH T1733143CA72A344B16CA1BE6732AE881531D4D1CA98C6EF992CEC34F944CEE04F4457A3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:gafgyt sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.115.19/arm4a8c760bb388ab5567e3fd98006fe4bc7d66e0832139af3c526de0c87709779de Gafgytelf gafgyt ua-wget
http://196.251.115.19/arm4tn/an/aelf ua-wget
http://196.251.115.19/arm524d041027fc805b2a992b08591e29ddc908fe7444f3acfb97421ec7972091fc3 Gafgytelf gafgyt ua-wget
http://196.251.115.19/arm6b525dcf67637d16f7fa706fe3f09fcb081174b5544a85c5f26966ffa456650ba Gafgytelf gafgyt ua-wget
http://196.251.115.19/i68676cd9f11b80ef1965dbcc0f5a291128a42765eea1f5249072453745c0ec3208f Gafgytelf gafgyt ua-wget
http://196.251.115.19/m681d4552bd34a7f0bb66ecd1182b8cda55577f75b53bd5d33153b7c61f45924b18 Gafgytelf gafgyt ua-wget
http://196.251.115.19/mipsd55cb83925f19c5788b9cfc1de5a8b77974ac1dfd8209bf3e67b177f2adc9235 Gafgytelf gafgyt ua-wget
http://196.251.115.19/mpsl51919576254b24acac956a09ec5d40c2f984e4533f6655ec0e1fdc14ced698eb Gafgytelf gafgyt ua-wget
http://196.251.115.19/ppc9914fd97c22e39750a1103b341238ac8509f6fac719d225a0dd33334d182d8a0 Gafgytelf gafgyt ua-wget
http://196.251.115.19/spc7a145aec20e0d6c25ec3f6163a4d70b00ad89854051d2680565785f46746d500 Gafgytelf gafgyt ua-wget
http://196.251.115.19/x866984aa53d93a9523a4ebf50f217a8a9a7bf7be6b50003737a2f74861e54d83fd Gafgytelf gafgyt ua-wget
http://196.251.115.19/sh41a69acae06c495d68ca9c45e1aaa0704d4148cbeceb09319823b1f28bc310390 Gafgytelf gafgyt ua-wget
http://196.251.115.19/arm79220d7cd7f6475d8b6d939b651f41089868e5aec3c8064e331d63d5353c1a8b1 Gafgytelf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-02T07:07:00Z UTC
Last seen:
2025-11-04T10:24:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.cx HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=856fb75c-1900-0000-9029-801b70090000 pid=2416 /usr/bin/sudo guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425 /tmp/sample.bin guuid=856fb75c-1900-0000-9029-801b70090000 pid=2416->guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425 execve guuid=938ea260-1900-0000-9029-801b7b090000 pid=2427 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=938ea260-1900-0000-9029-801b7b090000 pid=2427 execve guuid=c57d496a-1900-0000-9029-801b8f090000 pid=2447 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=c57d496a-1900-0000-9029-801b8f090000 pid=2447 execve guuid=8e6bac6a-1900-0000-9029-801b90090000 pid=2448 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=8e6bac6a-1900-0000-9029-801b90090000 pid=2448 clone guuid=1afe5f6b-1900-0000-9029-801b92090000 pid=2450 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=1afe5f6b-1900-0000-9029-801b92090000 pid=2450 execve guuid=20d7cb6b-1900-0000-9029-801b95090000 pid=2453 /usr/bin/wget net send-data guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=20d7cb6b-1900-0000-9029-801b95090000 pid=2453 execve guuid=57fdef6e-1900-0000-9029-801b9f090000 pid=2463 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=57fdef6e-1900-0000-9029-801b9f090000 pid=2463 execve guuid=74303e6f-1900-0000-9029-801ba0090000 pid=2464 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=74303e6f-1900-0000-9029-801ba0090000 pid=2464 clone guuid=d834576f-1900-0000-9029-801ba1090000 pid=2465 /usr/bin/rm guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=d834576f-1900-0000-9029-801ba1090000 pid=2465 execve guuid=9b29af6f-1900-0000-9029-801ba3090000 pid=2467 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=9b29af6f-1900-0000-9029-801ba3090000 pid=2467 execve guuid=6e32a674-1900-0000-9029-801baf090000 pid=2479 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=6e32a674-1900-0000-9029-801baf090000 pid=2479 execve guuid=1320e074-1900-0000-9029-801bb1090000 pid=2481 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=1320e074-1900-0000-9029-801bb1090000 pid=2481 clone guuid=cfadb875-1900-0000-9029-801bb6090000 pid=2486 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=cfadb875-1900-0000-9029-801bb6090000 pid=2486 execve guuid=84a20776-1900-0000-9029-801bb7090000 pid=2487 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=84a20776-1900-0000-9029-801bb7090000 pid=2487 execve guuid=67d1d67b-1900-0000-9029-801bc7090000 pid=2503 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=67d1d67b-1900-0000-9029-801bc7090000 pid=2503 execve guuid=2d48217c-1900-0000-9029-801bc9090000 pid=2505 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=2d48217c-1900-0000-9029-801bc9090000 pid=2505 clone guuid=e810b47c-1900-0000-9029-801bcd090000 pid=2509 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=e810b47c-1900-0000-9029-801bcd090000 pid=2509 execve guuid=f6edfc7c-1900-0000-9029-801bcf090000 pid=2511 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=f6edfc7c-1900-0000-9029-801bcf090000 pid=2511 execve guuid=5ac89282-1900-0000-9029-801bd8090000 pid=2520 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=5ac89282-1900-0000-9029-801bd8090000 pid=2520 execve guuid=06a1e482-1900-0000-9029-801bda090000 pid=2522 /tmp/i686 net guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=06a1e482-1900-0000-9029-801bda090000 pid=2522 execve guuid=22420484-1900-0000-9029-801bdf090000 pid=2527 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=22420484-1900-0000-9029-801bdf090000 pid=2527 execve guuid=1d5d4f84-1900-0000-9029-801be0090000 pid=2528 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=1d5d4f84-1900-0000-9029-801be0090000 pid=2528 execve guuid=a228f58a-1900-0000-9029-801bf1090000 pid=2545 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=a228f58a-1900-0000-9029-801bf1090000 pid=2545 execve guuid=c0e6618b-1900-0000-9029-801bf3090000 pid=2547 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=c0e6618b-1900-0000-9029-801bf3090000 pid=2547 clone guuid=9eb9f88b-1900-0000-9029-801bf7090000 pid=2551 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=9eb9f88b-1900-0000-9029-801bf7090000 pid=2551 execve guuid=87f77f8c-1900-0000-9029-801bfa090000 pid=2554 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=87f77f8c-1900-0000-9029-801bfa090000 pid=2554 execve guuid=87682c92-1900-0000-9029-801b080a0000 pid=2568 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=87682c92-1900-0000-9029-801b080a0000 pid=2568 execve guuid=186d9e92-1900-0000-9029-801b090a0000 pid=2569 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=186d9e92-1900-0000-9029-801b090a0000 pid=2569 clone guuid=81043894-1900-0000-9029-801b0e0a0000 pid=2574 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=81043894-1900-0000-9029-801b0e0a0000 pid=2574 execve guuid=f8f98894-1900-0000-9029-801b100a0000 pid=2576 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=f8f98894-1900-0000-9029-801b100a0000 pid=2576 execve guuid=93901d9a-1900-0000-9029-801b200a0000 pid=2592 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=93901d9a-1900-0000-9029-801b200a0000 pid=2592 execve guuid=4a16639a-1900-0000-9029-801b220a0000 pid=2594 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=4a16639a-1900-0000-9029-801b220a0000 pid=2594 clone guuid=868cf69a-1900-0000-9029-801b260a0000 pid=2598 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=868cf69a-1900-0000-9029-801b260a0000 pid=2598 execve guuid=92446f9c-1900-0000-9029-801b290a0000 pid=2601 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=92446f9c-1900-0000-9029-801b290a0000 pid=2601 execve guuid=d17ce8a2-1900-0000-9029-801b3c0a0000 pid=2620 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=d17ce8a2-1900-0000-9029-801b3c0a0000 pid=2620 execve guuid=aea44ea3-1900-0000-9029-801b3e0a0000 pid=2622 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=aea44ea3-1900-0000-9029-801b3e0a0000 pid=2622 clone guuid=8f0deba4-1900-0000-9029-801b450a0000 pid=2629 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=8f0deba4-1900-0000-9029-801b450a0000 pid=2629 execve guuid=818b3ba5-1900-0000-9029-801b470a0000 pid=2631 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=818b3ba5-1900-0000-9029-801b470a0000 pid=2631 execve guuid=1fc5ffaa-1900-0000-9029-801b560a0000 pid=2646 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=1fc5ffaa-1900-0000-9029-801b560a0000 pid=2646 execve guuid=c47160ab-1900-0000-9029-801b580a0000 pid=2648 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=c47160ab-1900-0000-9029-801b580a0000 pid=2648 clone guuid=276d85ac-1900-0000-9029-801b5d0a0000 pid=2653 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=276d85ac-1900-0000-9029-801b5d0a0000 pid=2653 execve guuid=9845e2ac-1900-0000-9029-801b5f0a0000 pid=2655 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=9845e2ac-1900-0000-9029-801b5f0a0000 pid=2655 execve guuid=c94362b2-1900-0000-9029-801b710a0000 pid=2673 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=c94362b2-1900-0000-9029-801b710a0000 pid=2673 execve guuid=92b1a8b2-1900-0000-9029-801b730a0000 pid=2675 /tmp/x86 net guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=92b1a8b2-1900-0000-9029-801b730a0000 pid=2675 execve guuid=4563dfb2-1900-0000-9029-801b760a0000 pid=2678 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=4563dfb2-1900-0000-9029-801b760a0000 pid=2678 execve guuid=0e691fb3-1900-0000-9029-801b780a0000 pid=2680 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=0e691fb3-1900-0000-9029-801b780a0000 pid=2680 execve guuid=4e74f6b8-1900-0000-9029-801b8b0a0000 pid=2699 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=4e74f6b8-1900-0000-9029-801b8b0a0000 pid=2699 execve guuid=90144bb9-1900-0000-9029-801b8c0a0000 pid=2700 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=90144bb9-1900-0000-9029-801b8c0a0000 pid=2700 clone guuid=a223e3b9-1900-0000-9029-801b900a0000 pid=2704 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=a223e3b9-1900-0000-9029-801b900a0000 pid=2704 execve guuid=62d631ba-1900-0000-9029-801b920a0000 pid=2706 /usr/bin/wget net send-data write-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=62d631ba-1900-0000-9029-801b920a0000 pid=2706 execve guuid=c8fde1bf-1900-0000-9029-801ba20a0000 pid=2722 /usr/bin/chmod guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=c8fde1bf-1900-0000-9029-801ba20a0000 pid=2722 execve guuid=b2504dc0-1900-0000-9029-801ba40a0000 pid=2724 /usr/bin/bash guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=b2504dc0-1900-0000-9029-801ba40a0000 pid=2724 clone guuid=8dd0dcc0-1900-0000-9029-801ba70a0000 pid=2727 /usr/bin/rm delete-file guuid=e6dd6d5f-1900-0000-9029-801b79090000 pid=2425->guuid=8dd0dcc0-1900-0000-9029-801ba70a0000 pid=2727 execve 95be8eb7-2750-51b0-b874-c156db3b2ac1 196.251.115.19:80 guuid=938ea260-1900-0000-9029-801b7b090000 pid=2427->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 133B guuid=20d7cb6b-1900-0000-9029-801b95090000 pid=2453->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 134B guuid=9b29af6f-1900-0000-9029-801ba3090000 pid=2467->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 133B guuid=84a20776-1900-0000-9029-801bb7090000 pid=2487->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 133B guuid=f6edfc7c-1900-0000-9029-801bcf090000 pid=2511->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 133B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=06a1e482-1900-0000-9029-801bda090000 pid=2522->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1e3ee983-1900-0000-9029-801bdd090000 pid=2525 /tmp/i686 guuid=06a1e482-1900-0000-9029-801bda090000 pid=2522->guuid=1e3ee983-1900-0000-9029-801bdd090000 pid=2525 clone guuid=451cf383-1900-0000-9029-801bde090000 pid=2526 /tmp/i686 net send-data zombie guuid=1e3ee983-1900-0000-9029-801bdd090000 pid=2525->guuid=451cf383-1900-0000-9029-801bde090000 pid=2526 clone b064a61d-f5f4-5adf-82f1-0c68592fc11f 196.251.115.19:4444 guuid=451cf383-1900-0000-9029-801bde090000 pid=2526->b064a61d-f5f4-5adf-82f1-0c68592fc11f send: 65B guuid=1d5d4f84-1900-0000-9029-801be0090000 pid=2528->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 132B guuid=87f77f8c-1900-0000-9029-801bfa090000 pid=2554->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 133B guuid=f8f98894-1900-0000-9029-801b100a0000 pid=2576->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 133B guuid=92446f9c-1900-0000-9029-801b290a0000 pid=2601->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 132B guuid=818b3ba5-1900-0000-9029-801b470a0000 pid=2631->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 132B guuid=9845e2ac-1900-0000-9029-801b5f0a0000 pid=2655->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 132B guuid=92b1a8b2-1900-0000-9029-801b730a0000 pid=2675->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d3eccab2-1900-0000-9029-801b740a0000 pid=2676 /tmp/x86 guuid=92b1a8b2-1900-0000-9029-801b730a0000 pid=2675->guuid=d3eccab2-1900-0000-9029-801b740a0000 pid=2676 clone guuid=ba7ed1b2-1900-0000-9029-801b750a0000 pid=2677 /tmp/x86 net send-data zombie guuid=d3eccab2-1900-0000-9029-801b740a0000 pid=2676->guuid=ba7ed1b2-1900-0000-9029-801b750a0000 pid=2677 clone guuid=ba7ed1b2-1900-0000-9029-801b750a0000 pid=2677->b064a61d-f5f4-5adf-82f1-0c68592fc11f send: 65B guuid=0e691fb3-1900-0000-9029-801b780a0000 pid=2680->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 132B guuid=62d631ba-1900-0000-9029-801b920a0000 pid=2706->95be8eb7-2750-51b0-b874-c156db3b2ac1 send: 133B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-11-03 02:41:08 UTC
File Type:
Text (Shell)
AV detection:
25 of 38 (65.79%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Malware Config
C2 Extraction:
196.251.115.19:4444
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 2d388917582a8cb3e76fdd2cfddd009a456feb3863328e018821bb359d74ff12

(this sample)

  
Delivery method
Distributed via web download

Comments